HomeSecurityFBI: Hackers are abusing email forwarding rules for attacks!

FBI: Hackers are abusing email forwarding rules for attacks!

The FBI is warning that hackers are increasingly relying on email forwarding rules to hide their presence in compromised accounts . In a Private Industry Alert PIN ) issued yesterday, the FBI said this technique has been observed in BEC attacks reported over the summer. The hackers’ technique relies on a feature found in some services called “automatic email forwarding rules.” This is a feature that allows the owner of an address to set up “rules” that forward an incoming email to another address if certain criteria are met.

FBI: Hackers are abusing email forwarding rules for attacks!

Hackers rely on automatic email forwarding rules as they allow them to receive copies of all incoming messages in one email, without having to log into an account every day and risk triggering warning for a “suspicious” connection.

Additionally, the FBI noted that it received numerous reports over the summer that this technique has been used repeatedly by gangs involved in BEC scams. This is a form of cybercrime where hackers compromise email accounts and then send emails from the compromised account, trying to convince other employees or business partners to authorize payments to accounts controlled by the attackers.

FBI: Hackers are abusing email forwarding rules for attacks!

The FBI cited two cases in which hackers behind BEC scams abused email forwarding rules during their attacks:

  • In August 2020, hackers created automatic email forwarding rules in the recently upgraded web client of a US. The webmail did not sync with the desktop application and went unnoticed by the victim company, which only followed the automatic forwarding rules in the desktop client. Additionally, RSS was not enabled in the desktop application. After the hackers gained access to the network, they spoofed a well-known international supplier. They created a domain that had a similar spelling to the victim’s and communicated with the vendor using a UK to further increase the likelihood of payment. Notably, the hackers made off with $175,000 from the victim.
  • In August 2020, another similar incident occurred, where the same hackers created three forwarding rules within the webmail used by a construction company. The first rule automatically forwarded any emails with the search terms “bank”, “payment”, “invoice”, “bank transfer” or “check” to the hackers’ email address. The other two rules were based on the sender’s domain and forwarded back to the same email address.

FBI officials say that numerous companies around the world fall victim to this technique because they don’t synchronize email settings for web-based accounts with desktop clients. This, in turn, limits visibility for cybersecurity administrators and the company’s security software, which can be configured and detect forwarding rules but can remain “blind” to new rules until synchronization occurs.

FBI: Hackers are abusing email forwarding rules for attacks!

FBI PIN contains a series of key mitigations and solutions for system administrators to address this specific attack vector and prevent future abuse.

As ZDNet reports, the PIN comes after the FBI reported earlier this year that BEC scams were, by far, the most popular form of cybercrime in 2019, accounting for 50% of cyber losses reported last year.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS